Storage Limitation: GDPR Privacy Principles

Storage limitation, or keeping data for no longer than necessary, is a key part of GDPR compliance. The GDPR consists of several fundamental principles that organisations and individuals must abide by to ensure the lawful and ethical processing of personal data. In this article, we will delve into this principle, exploring its significance, the obligations it imposes, and how it affects data handling practices.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

What Does The GDPR Say?

Article 5(e) of the GDPR (brought into UK law by the Data Protection Act 2018) says that “data shall kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes subject to implementation of the appropriate technical and organisational measures required by the GDPR in order to safeguard the rights and freedoms of individuals (‘storage limitation’).

What Does This Mean?

The fifth data protection principle within the GDPR is a pillar of responsible data management. It emphasises that personal data should not be stored for longer than is necessary for the purpose for which it was collected. In short it means:

  • you must understand what you need personal data for

  • decide when this processing activity is due to end

  • you must have arrangements for the deletion of personal data when it is no longer needed

To grasp its significance, let’s break it down:

Defining Storage Limitation

The principle of storage limitation aims to prevent the indefinite retention of personal data. Organisations must establish clear criteria for determining how long data is kept, and this period should align with the intended purpose for which the data was collected.

That means defining retention periods for different categories of personal data and different processing activities. These might include:

  • marketing to potential customers

  • employment, such as recruitment or payroll

  • delivering products and services to existing customers

Archiving Purposes and Research

As the text of the GDPR notes personal data may be retained in identifiable form for archiving purposes and for research. However, appropriate steps have to be taken to ensure people’s “rights and freedoms” are protected. That means at a minimum having the right levels of security and access restriction to prevent a data breach.

You must have a clear purpose in mind if you archive personal data. Don’t keep it “just in case”. You also need to be clear about why anonymised or pseudonymised data would not meet your needs. Finally, you cannot reuse data retained for research purposes for anything else.

Aligning Storage Limitation with Data Minimisation

Storage limitation is closely tied to the third data protection principle, data minimisation. It is much easier to abide by the principle of storage limitation if only the minimum necessary data is collected in the first place. Again, this means understanding what data you need and what you will be processing it for.

  • find out more about the principle of data minimisation here.

The Importance of Storage Limitation

Although it is a statutory requirement to comply with the GDPR, there are wider benefits to getting compliance with the storage limitation principle right.

Safeguarding Individual Privacy

By adhering to storage limitation, organisations respect the privacy of individuals. By ensuring data are not kept indefinitely you can reduce risk of a data breach, and avoid the consequences of lost or stolen data.

Enhancing Data Accuracy

Reducing the volume of stored data can lead to better data accuracy. Outdated or irrelevant information can introduce errors into datasets, which may impact decisions and processes reliant on this data.

Improving Efficiency

By reducing the volume of personal data that you have you will make it easier and quicker to find the data you need. It can also save money because there are costs associated with both storing data, and processing data.

The Obligations Imposed by Storage Limitation

The GDPR imposes specific obligations on data controllers and processors regarding the application of the storage limitation principle. The technical and organisational measures that need to be put in place are not difficult to do, but they are important for GDPR compliance.

Determining Retention Periods

Organisations must establish and document the retention periods for different categories of personal data. These retention periods must be reasonable and aligned with the data’s intended purpose.

Your retention periods should be set out in a clear retention policy.

For example, some employment information will need to be retained for decades if it relates to pensions. Alternatively some data, like sickness absence, may only be needed for a short while – perhaps a year.

It is worth noting retention periods are a minimum not a maximum. If you decide to keep some data items for longer than the retention period you need to be clear why.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

Periodic Review and Deletion

Regularly reviewing and deleting data that surpasses its retention period is important. This ensures that data is not stored indefinitely and is promptly disposed of when it is no longer necessary.

Then of course the data need to be deleted. Hard copy information should be shredded or disposed of through confidential waste disposal. Electronic data should be thoroughly deleted and it should not be accessible via backups or in a “deleted items” folder.

storage limitation

Storage Limitation Best Practices

For organisations and individuals navigating data protection regulations, following best practices is vital:

Record of Processing Activity

Maintaining a comprehensive inventory of the personal data you collect and store is the first step in adhering to storage limitation. This inventory should include details such as the data’s source, purpose, and retention period.

This inventory is known as a Record of Processing Activity (ROPA) and is one of the requirements of data protection law.

Secure Data Disposal

Develop secure systems for data erasure that has reached the end of its retention period. This includes digital data, physical records, and ensuring that no residual copies exist.

Data Subject Rights

Be prepared to respond to data subject requests regarding the deletion or modification of their personal data. Implementing efficient processes to address such requests is crucial.

There are two key rights to be aware of when it comes to the principle of storage limitation:

  • Right of Access: when people make subject access requests you must tell them what personal data you have, what you use it for, and who you have shared it with (among other things). It is therefore important to know what data you have and what data has been deleted.

  • Right of Erasure: this is also known as “the right to be forgotten”. It means in some circumstances people can ask for the deletion of their personal data. This is not an absolute right and will only apply where you do not need to keep the data for your own business.

Learn More About the GDPR

 

This GDPR training course includes the following modules:

  • what are personal data?;
  • the privacy principles;
  • privacy by design
  • accountability under the GDPR;
  • people’s rights under the GDPR;
  • consent and other lawful routes for data sharing;
  • data flow mapping and records of processing activity;
  • Data Protection Impact Assessments;
  • restricted and special category data
  • Data security and Data Breaches

Plus six months’ free post course support to help you apply your learning

 

 

Conclusion: Key Takeaways on Storage Limitation

The fifth data protection principle, storage limitation, is an integral component of the GDPR’s framework. Understanding and applying this principle is not just a legal requirement; it is an ethical obligation that helps safeguard individual privacy, enhance data accuracy, and mitigate data-related risks. By adopting best practices for data storage and following legal requirements, organisations and individuals can ensure that personal data is retained only for as long as necessary, promoting responsible and respectful data management.